SuSE Linux SuSEWM Configuration File Insecure Temporary File Vulnerability
BID:8778
Info
SuSE Linux SuSEWM Configuration File Insecure Temporary File Vulnerability
| Bugtraq ID: | 8778 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 06 2003 12:00AM |
| Updated: | Oct 06 2003 12:00AM |
| Credit: | Discovery credited to Stefan Nordhausen. |
| Vulnerable: |
S.u.S.E. Linux Professional 8.2 |
| Not Vulnerable: | |
Discussion
SuSE Linux SuSEWM Configuration File Insecure Temporary File Vulnerability
A problem exists in the SuSEWM configuration file used by SuSEConfig. Because of this, it may be possible for a local attacker to gain elevated privileges.
A problem exists in the SuSEWM configuration file used by SuSEConfig. Because of this, it may be possible for a local attacker to gain elevated privileges.
Exploit / POC
SuSE Linux SuSEWM Configuration File Insecure Temporary File Vulnerability
A proof of concept exploit has been made available.
A proof of concept exploit has been made available.
Solution / Fix
SuSE Linux SuSEWM Configuration File Insecure Temporary File Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SuSE Linux SuSEWM Configuration File Insecure Temporary File Vulnerability
References:
References:
- 8.2 Product Page (SuSE)
- Re: Local root exploit in SuSE Linux 8.2Pro (Roman Drahtmueller
)